QuestionQ85

Cortex XSOAR

Which action should an administrator take to create automated response actions when a user account is compromised, allowing an attacker to upload data to an external IP address and infect a machine on the company network with malware?

  • A Create automation rules in Cortex XDR that will trigger for each alert.
  • B Create a script in Cortex XSOAR that will run a playbook based on the scenario.
  • C Create playbook triggers in Cortex XSIAM and run playbooks for each alert.
  • D Map the events as type of Cortex XSOAR incident, then run a playbook.
Explanation

Cortex XSOAR classifies ingested events into an incident type and maps their data into incident fields. An incident type can be configured with a default playbook, enabling the appropriate response playbook to run automatically for the correlated compromise scenario. Classification and mapping — Cortex XSOAR

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!